1 From f57dcf4c72113c745d83f1c65f7291299f65c14f Mon Sep 17 00:00:00 2001
2 From: Trond Myklebust <trond.myklebust@hammerspace.com>
3 Date: Wed, 13 Feb 2019 09:21:38 -0500
4 Subject: NFS: Fix I/O request leakages
6 From: Trond Myklebust <trond.myklebust@hammerspace.com>
8 commit f57dcf4c72113c745d83f1c65f7291299f65c14f upstream.
10 When we fail to add the request to the I/O queue, we currently leave it
11 to the caller to free the failed request. However since some of the
12 requests that fail are actually created by nfs_pageio_add_request()
13 itself, and are not passed back the caller, this leads to a leakage
14 issue, which can again cause page locks to leak.
16 This commit addresses the leakage by freeing the created requests on
17 error, using desc->pg_completion_ops->error_cleanup()
19 Signed-off-by: Trond Myklebust <trond.myklebust@hammerspace.com>
20 Fixes: a7d42ddb30997 ("nfs: add mirroring support to pgio layer")
21 Cc: stable@vger.kernel.org # v4.0: c18b96a1b862: nfs: clean up rest of reqs
22 Cc: stable@vger.kernel.org # v4.0: d600ad1f2bdb: NFS41: pop some layoutget
23 Cc: stable@vger.kernel.org # v4.0+
24 Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
27 fs/nfs/pagelist.c | 26 +++++++++++++++++++++-----
28 1 file changed, 21 insertions(+), 5 deletions(-)
30 --- a/fs/nfs/pagelist.c
31 +++ b/fs/nfs/pagelist.c
32 @@ -989,6 +989,17 @@ static void nfs_pageio_doio(struct nfs_p
37 +nfs_pageio_cleanup_request(struct nfs_pageio_descriptor *desc,
38 + struct nfs_page *req)
42 + nfs_list_remove_request(req);
43 + nfs_list_add_request(req, &head);
44 + desc->pg_completion_ops->error_cleanup(&head);
48 * nfs_pageio_add_request - Attempt to coalesce a request into a page list.
49 * @desc: destination io descriptor
50 @@ -1026,10 +1037,8 @@ static int __nfs_pageio_add_request(stru
51 nfs_page_group_unlock(req);
53 nfs_pageio_doio(desc);
54 - if (desc->pg_error < 0)
56 - if (mirror->pg_recoalesce)
58 + if (desc->pg_error < 0 || mirror->pg_recoalesce)
59 + goto out_cleanup_subreq;
60 /* retry add_request for this subreq */
61 nfs_page_group_lock(req);
63 @@ -1062,6 +1071,10 @@ err_ptr:
64 desc->pg_error = PTR_ERR(subreq);
65 nfs_page_group_unlock(req);
69 + nfs_pageio_cleanup_request(desc, subreq);
73 static int nfs_do_recoalesce(struct nfs_pageio_descriptor *desc)
74 @@ -1169,11 +1182,14 @@ int nfs_pageio_add_request(struct nfs_pa
75 if (nfs_pgio_has_mirroring(desc))
76 desc->pg_mirror_idx = midx;
77 if (!nfs_pageio_add_request_mirror(desc, dupreq))
79 + goto out_cleanup_subreq;
86 + nfs_pageio_cleanup_request(desc, dupreq);
88 /* remember fatal errors */
89 if (nfs_error_is_fatal(desc->pg_error))